The world is built on open source. Keep building.

Companies run Workbrew so that developers can keep Homebrew at work and stay productive.

Why is Workbrew on my Mac?

Your company chose to keep Homebrew. Many don’t.

Regulated companies often don’t allow Homebrew. IT has to account for every piece of software on every Mac, and one command that installs anything is hard to account for. So developers get a limited list of approved installers, or install Homebrew quietly and hope nobody asks

Your company went a different way. It put Workbrew on this Mac so that brew is the supported, sanctioned way to get your tools, the inventory IT is accountable for is the one Homebrew already keeps, and the auditor’s questions get answered without anyone taking your tools away.

Open source shouldn’t have to live in the shadows to be allowed at work.

What changes on your Mac

The same brew, with a few differences

Here’s what changes on a Workbrew-managed Mac, and what doesn’t.

What doesn’t change

  • Homebrew’s high bar for security.
  • brew install, brew upgrade, brew search and the rest work as before.
  • The same packages and apps, from Homebrew’s catalog.
  • Brewfiles, still the best way to set up a Mac. Your company can ship one on day one.

What does change

What Workbrew can see and do on your Mac

The inventory your company is accountable for is all of what Workbrew collects.

What the Agent reports

  • What’s installed through Homebrew, npm, and VS Code, and which versions.
  • Whether any of it has a known vulnerability.
  • The brew commands run through it, so there’s an audit trail.

What your admin can do

  • Install software to your Mac.
  • Upgrade a vulnerable version.
  • Remove a package.

Every one of those actions is logged.

What it can’t see

  • Your files.
  • Your browser.
  • What you type.

Workbrew manages the software on your Mac, not you.

We built Workbrew for you

Policies explain themselves.

When a policy stops an install, the message says so and tells you what to do next. It doesn’t fail silently.

Request what you need.

If a title you need isn’t allowed, you can request it from the Workbrew app. Your admin approves it from the Console and the app tells you when it’s ready.

Guardrails on the admin side too.

Actions in the Console that could break a developer’s environment carry a strong warning before an admin can run them.

Your company’s tools, one install away.

Internal tools published through a private tap are just a brew install away. No more wrestling with git repo credentials.

zsh — brew
brew install brave-browserError: The following casks are not allowed by Acme Corp IT: brave-browserRun `brew workbrew request brave-browser` to ask your admin to allow it.Contact us on Slack in #security with questionsbrew workbrew request brave-browserPackage request for brave-browser has been queued and will be sent to Acme Corp IT.You’ll be able to install once they approve the request.

A cask that isn’t allowed, and the request that fixes it. No silent failure, and a person to ask

Your Mac stays your developer environment

Workbrew manages the software, not you. If something isn’t behaving the way this page says it should, the troubleshooting docs cover the common snags, from PATH to brew services.